Orange textured background

US state law

ICDPA and browser fingerprinting

Iowa is the lightest US state privacy law in 2026. No Data Protection Assessment, no Universal Opt-Out Mechanism, no profiling opt-out, and the longest cure period of any cluster state - here is what that means for a fingerprinting deployment.

Reviewed

RegionIowa, USA
RegulatorIowa Attorney General (Consumer Protection Division)
Effective1 January 2025
Max penaltyUp to $7,500 per violation in civil penalties
Status in-force

Iowa is the lightest US state privacy law in 2026

The Iowa Consumer Data Protection Act (ICDPA) is codified at Iowa Code Chapter 715D (sections 715D.1 through 715D.9) and took effect on 1 January 2025. It was enacted as Iowa Senate File 262 in 2023 and follows the basic architecture of the 'Virginia cluster': personal-data-as-opt-out, sensitive-data-as-opt-in, AG enforcement, no private right of action.

What sets Iowa apart from every other cluster state is how many of the harder-to-implement obligations it quietly omits. Iowa has no Data Protection Assessment requirement. Iowa has no Universal Opt-Out Mechanism recognition - the Global Privacy Control signal carries no legal weight under ICDPA. Iowa has no profiling opt-out - a consumer cannot opt out of automated profiling under the law, even when the decision has legal or similarly significant effects. And Iowa's cure period is 90 days, the longest of any US state law, with no statutory provision to sunset it.

The framing that best describes ICDPA is not what it requires, but what it does not require. A deployment that already clears VCDPA, CPA, or CTDPA is almost certainly already compliant with Iowa. The reverse does not hold: a deployment built to Iowa's minimum standards would fail in Virginia, Colorado, and Connecticut.

What ICDPA says about fingerprinting

ICDPA does not use the words 'fingerprinting', 'device identifier', or 'browser fingerprint'. It defines 'personal data' at §715D.1 as 'any information that is linked or reasonably linkable to an identified or identifiable natural person'. A browser or device fingerprint hash - composed of canvas rendering output, font enumeration, GPU vendor strings, audio context, time zone, installed plugins, and similar device characteristics - qualifies as personal data the moment a controller uses it to recognise a returning Iowa consumer. The hash does not need to be tied to a name, an email address, or a payment instrument; the linkability test is satisfied by the fact that the same hash maps back to the same browsing session across visits.

The classification as personal data is the same across every Virginia-cluster state. The operational consequences that follow the classification are where Iowa diverges - and diverges substantially in the controller's favour.

When ICDPA applies to you

Section 715D.2 applies ICDPA to controllers that conduct business in Iowa or produce products or services targeted to Iowa residents, and that either (a) control or process the personal data of 100,000 or more Iowa consumers in a calendar year, or (b) control or process the personal data of 25,000 or more Iowa consumers and derive more than 50% of gross revenue from the sale of personal data.

The applicability thresholds mirror VCDPA and differ from Colorado's CPA in two ways. First, Iowa's second leg (the 25,000-consumer test) requires more than 50% of gross revenue from sale - a much higher bar than Colorado's 'any revenue from sale' formulation. Second, Iowa has no revenue gate like Utah's $25 million floor; the consumer-count tests apply to companies of any size.

The definition of 'consumer' at §715D.1 means a natural person who is an Iowa resident acting in an individual or household context. Employees and individuals acting in a commercial or employment capacity are excluded. A fingerprint captured on an internal HR portal or a B2B SaaS product used exclusively by business customers does not trigger ICDPA obligations.

The opt-out triggers: what Iowa actually requires

Section 715D.3 grants Iowa consumers the right to opt out of two categories of processing: targeted advertising and sale of personal data. Those are the only two opt-out triggers. There is no profiling opt-out. A controller using a fingerprint as one input to an automated credit score, insurance pricing model, or employment screen does not owe an Iowa consumer an opt-out right for that processing under ICDPA.

Targeted advertising under §715D.1 means displaying advertisements to a consumer where the advertisement is selected based on personal data obtained from the consumer's activities across non-affiliated websites or online applications over time. Recognising a returning visitor by their fingerprint hash and serving cross-site behavioural ads is the core case. First-party retargeting on your own site, frequency capping, and contextual advertising are excluded.

Sale of personal data under ICDPA requires monetary consideration - the same narrow definition used by Virginia and Utah. Sharing fingerprint hashes with an ad-tech partner for non-monetary value (audience extension, data co-ops, mutual lift) is not a sale under ICDPA. A data broker that sells a packaged fingerprint-enriched audience segment for a dollar amount is engaging in a sale.

There is no Universal Opt-Out Mechanism requirement. Iowa does not mandate that controllers recognise the Global Privacy Control browser signal. A controller operating only in Iowa may run an on-site opt-out preference centre without any GPC header check and be fully compliant. A controller operating in Iowa and any UOOM state (Colorado, Connecticut, Oregon, Montana, Delaware, New Hampshire) still needs the GPC check for those other states.

Common fingerprinting purposes under ICDPA

PurposePersonal data under ICDPA?DPA required?Opt-out right applies?
Anti-fraud at login or paymentYesN/A (Iowa has no DPA requirement)No
Account-takeover detectionYesN/ANo
Bot mitigation on a public formYesN/ANo
Session continuity and anonymous analyticsYesN/ANo
Cross-site targeted advertisingYesN/AYes (targeted advertising)
Selling fingerprint-derived audience segments for a feeYesN/AYes (sale - monetary consideration)
Sharing fingerprint hashes for non-monetary mutual liftYesN/AProbably no (narrow monetary-only sale definition)
Profiling for credit / insurance / employmentYesN/ANo (ICDPA has no profiling opt-out)
Frequency capping on your own siteYesN/ANo (first-party carve-out)
Fingerprinting employees on an internal toolNo (employee carve-out)N/ANo

No Data Protection Assessment requirement

Every other Virginia-cluster state except Utah requires a documented Data Protection Assessment before engaging in targeted advertising, sale, sensitive-data processing, or covered profiling. Iowa does not. There is no §715D.X equivalent of VCDPA's §59.1-580 or CPA's 4 CCR 904-3 Rule 8. The Iowa AG cannot ground an enforcement action on the absence of an assessment.

That absence is a paperwork forgiveness clause, not a content-of-thinking forgiveness clause. The risks that a DPA exercise surfaces - overretention of fingerprint hashes, undisclosed recipients, inadequate de-identification claims, opt-out flows that break the anti-fraud path - are real risks regardless of whether Iowa requires the documentation. A controller that skips the DPA exercise because Iowa does not mandate it and later finds itself defending a pattern of processing to an Iowa AG inquiry will have fewer internal records to rely on.

The practical implication: if you operate in any other cluster state (Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, Tennessee, New Hampshire, or New Jersey), you already need to run the DPA exercise for those states. Iowa is a free pass once the work is done. Do not skip it just because Iowa is in scope.

The 90-day cure period: the longest in the cluster

Section 715D.7 gives controllers 90 days to cure a violation after receiving written notice from the Iowa Attorney General. That is the longest statutory cure period of any US state privacy law. Colorado's cure period sunset on 1 July 2025. Connecticut's sunset on the same date. Oregon, Montana, Delaware, and New Hampshire all have shorter or sunset cure periods. Virginia retains a cure window but at a shorter length.

Critically, Iowa's 90-day window is not scheduled to sunset. There is no provision in Iowa Senate File 262 or Chapter 715D that terminates the cure right after a fixed date or after a certain number of violations. The Iowa legislature did not include a sunset mechanism, and no amendment has been introduced to add one.

The practical consequence: a first-time Iowa compliance gap - a missing opt-out mechanism, an unscoped fingerprint-for-targeted-ads pipeline, an unclear privacy notice - is curable before any civil penalty attaches. That does not justify a 'fix it when we get the letter' posture, but it does mean Iowa is the most operationally forgiving state in the cluster for documentation gaps discovered during an internal audit.

Enforcement context: Iowa's record and parallel authority

  • ICDPA only took effect on 1 January 2025. The Iowa AG's Consumer Protection Division has not yet published any ICDPA-specific enforcement actions, settlements, or formal guidance letters at the time of writing. Iowa's enforcement record is new and sparse by design.
  • The Iowa AG's Consumer Protection Division has a long pre-ICDPA track record of enforcement under the Iowa Consumer Fraud Act (Iowa Code §714H), which prohibits unfair or deceptive consumer practices. Controllers that engage in misleading privacy-notice disclosures or ignore stated opt-out requests may face parallel Consumer Fraud Act exposure even where ICDPA penalties are low or have not yet been tested.
  • The Iowa Consumer Fraud Act allows the AG to seek injunctive relief, civil penalties, and restitution outside the ICDPA framework. A fingerprinting deployment that claims 'we do not track you' in a privacy notice while running cross-site behavioural advertising is the kind of fact pattern that has historically attracted Iowa Consumer Fraud Act scrutiny independent of any sector-specific privacy law.
  • There is no private right of action under ICDPA. Iowa consumers cannot sue controllers directly for ICDPA violations. Enforcement is exclusively through the AG's office.
  • Civil penalties under §715D.7 cap at $7,500 per violation, matching Virginia's maximum. The 90-day cure period means penalties are unlikely to attach for first-time violations where the controller promptly remedies the issue on notice.

How Benny the Doorman fits into an ICDPA-aware deployment

An ICDPA-aware Benny deployment is the simplest configuration in the Virginia-cluster matrix. Iowa does not require UOOM handling, does not require a DPA, and does not require a profiling opt-out. The two remaining obligations are an opt-out mechanism for targeted advertising and an opt-out mechanism for sale - both of which a VCDPA-compliant deployment already satisfies.

Three steps for an Iowa-only deployment. First, implement an on-site opt-out preference mechanism covering targeted advertising and sale. Iowa does not mandate that a specific technical signal (like GPC) be honoured, so a clear on-site opt-out centre is sufficient. If your deployment also covers Colorado, Connecticut, or any other UOOM state, add the GPC header check for those states - Iowa gets the benefit as a free pass.

Second, scope the Benny fingerprint call behind the opt-out signal for any targeted-advertising or sale-purpose flow. Anti-fraud, bot mitigation, analytics, and session continuity flows do not require gating. Those purpose lanes can run unconditionally under ICDPA (sensitive-data rules aside).

Third, treat the absence of an Iowa DPA requirement as a paperwork forgiveness clause, not a signal to skip the DPA exercise. Run the assessment for your Virginia, Colorado, or Connecticut obligations - Benny's documentation already provides the technical inputs on signal categories, retention defaults, and per-call data flows. Iowa controllers who have completed the exercise for other states are already prepared if the Iowa AG issues informal guidance or if the legislature adds a DPA requirement in a future amendment cycle.

Frequently asked questions

Is browser fingerprinting illegal under ICDPA?

No. Fingerprinting is not banned in Iowa. It is regulated as personal data under Iowa Code §715D.1 when the fingerprint hash can be reasonably linked to an identified or identifiable Iowa consumer. Lawful use under ICDPA requires honouring opt-out requests for targeted advertising and sale. Iowa does not require a Data Protection Assessment, does not require Universal Opt-Out Mechanism support, and does not provide a profiling opt-out - making ICDPA the lightest fingerprinting compliance obligation of any US state law in 2026.

Does Iowa require a Data Protection Assessment for fingerprinting?

No. Iowa is one of only two cluster states, along with Utah, that does not require a Data Protection Assessment before deploying fingerprinting for targeted advertising, sale, sensitive-data processing, or covered profiling. The Iowa AG cannot ground an enforcement action on a missing assessment. That said, the absence of the Iowa requirement is a paperwork forgiveness clause, not a signal to skip the DPA exercise - if you operate in any other cluster state, you already need the assessment for those obligations.

Do I need to honour Global Privacy Control under ICDPA?

No. Iowa does not recognise Universal Opt-Out Mechanisms and does not require controllers to honour the GPC browser signal. An Iowa-only deployment can run an on-site opt-out preference centre without a GPC header check and be fully compliant. A deployment covering Iowa and any UOOM state - Colorado, Connecticut, Oregon, Montana, Delaware, or New Hampshire - still needs the GPC check for those states.

Can I profile Iowa consumers without offering an opt-out?

Under ICDPA specifically, yes. Iowa is one of only two US state laws, along with Utah, that omits a profiling opt-out from the consumer rights catalogue. A controller using a fingerprint hash as one input to an automated credit, insurance, or employment decision does not owe an Iowa consumer a statutory opt-out for that processing under ICDPA. Federal laws (FCRA, ECOA) and other Iowa consumer-protection statutes may apply independently of ICDPA's silence on profiling.

How long is the cure period under Iowa's privacy law?

90 days from written notice from the Iowa Attorney General - the longest cure period of any US state privacy law. Unlike Colorado, Connecticut, Oregon, Montana, Delaware, and New Hampshire, Iowa's cure window is not scheduled to sunset. There is no provision in Iowa Code Chapter 715D that terminates the cure right after a fixed date or after a set number of violations.

How is Iowa different from Utah for fingerprinting compliance?

Both Iowa and Utah omit a Data Protection Assessment requirement and a profiling opt-out. Iowa goes further by also omitting the Universal Opt-Out Mechanism recognition that is not required by Utah but adopted by most other cluster states. Iowa's cure period is 90 days versus Utah's 30 days. Utah has a $25 million revenue gate at applicability that Iowa does not - meaning Iowa's consumer-count thresholds apply to companies of any size. In every practical dimension, Iowa imposes fewer obligations than Utah.

What are the fines for non-compliant fingerprinting under ICDPA?

Civil penalties under Iowa Code §715D.7 cap at $7,500 per violation, matching Virginia's maximum. The Iowa AG must provide written notice and a 90-day cure window before civil penalties can attach for first-time violations. There is no private right of action and no class-action exposure. Iowa's enforcement record is brand new as of 2025 and no ICDPA-specific settlements have been published.

Does the Iowa Consumer Fraud Act create parallel exposure for fingerprinting?

Potentially yes. Iowa Code §714H (Iowa Consumer Fraud Act) prohibits unfair and deceptive consumer practices and predates ICDPA. A controller that misrepresents its fingerprinting practices in a privacy notice - for example claiming 'we do not track you across sites' while running cross-site behavioural advertising based on fingerprint hashes - may face Consumer Fraud Act scrutiny independent of any ICDPA analysis. The AG's Consumer Protection Division has a long track record of §714H enforcement and does not need ICDPA as an authority to pursue misleading privacy disclosures.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06